{ "type": "bundle", "id": "bundle--18b3f168-44f9-4dfc-9c4d-9a0fc79a8e88", "spec_version": "2.0", "objects": [ { "modified": "2023-04-12T13:21:41.276Z", "name": "CURIUM", "description": "[CURIUM](https://attack.mitre.org/groups/G1012) is an Iranian threat group first reported in November 2021 that has invested in building a relationship with potential targets via social media over a period of months to establish trust and confidence before sending malware. Security researchers note [CURIUM](https://attack.mitre.org/groups/G1012) has demonstrated great patience and persistence by chatting with potential targets daily and sending benign files to help lower their security consciousness.(Citation: Microsoft Iranian Threat Actor Trends November 2021)", "aliases": [ "CURIUM" ], "x_mitre_deprecated": false, "x_mitre_version": "1.0", "type": "intrusion-set", "id": "intrusion-set--3ea7add5-5b8f-45d8-b1f1-905d2729d62a", "created": "2023-01-13T20:51:13.494Z", "created_by_ref": "identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5", "revoked": false, "external_references": [ { "source_name": "mitre-attack", "url": "https://attack.mitre.org/groups/G1012", "external_id": "G1012" }, { "source_name": "Microsoft Iranian Threat Actor Trends November 2021", "description": "MSTIC. (2021, November 16). Evolving trends in Iranian threat actor activity \u2013 MSTIC presentation at CyberWarCon 2021. Retrieved January 12, 2023.", "url": "https://www.microsoft.com/en-us/security/blog/2021/11/16/evolving-trends-in-iranian-threat-actor-activity-mstic-presentation-at-cyberwarcon-2021" } ], "object_marking_refs": [ "marking-definition--fa42a846-8d90-4e51-bc29-71d5b4802168" ], "x_mitre_domains": [ "enterprise-attack" ], "x_mitre_attack_spec_version": "3.1.0", "x_mitre_modified_by_ref": "identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5" } ] }